Логотип exploitDog
bind:"GHSA-46cw-54vx-86g5" OR bind:"CVE-2022-41974"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-46cw-54vx-86g5" OR bind:"CVE-2022-41974"

Количество 21

Количество 21

github логотип

GHSA-46cw-54vx-86g5

около 3 лет назад

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2022-41974

около 3 лет назад

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-41974

около 3 лет назад

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2022-41974

около 3 лет назад

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-41974

около 3 лет назад

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword which is mishandled because arithmetic ADD is used instead of bitwise OR.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2022-41974

около 3 лет назад

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to ...

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3715-1

около 3 лет назад

Security update for multipath-tools

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3714-1

около 3 лет назад

Security update for multipath-tools

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3713-1

около 3 лет назад

Security update for multipath-tools

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3712-1

около 3 лет назад

Security update for multipath-tools

EPSS: Низкий
rocky логотип

RLSA-2022:7192

около 3 лет назад

Important: device-mapper-multipath security update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7192

около 3 лет назад

ELSA-2022-7192: device-mapper-multipath security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7186

около 3 лет назад

ELSA-2022-7186: device-mapper-multipath security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7185

около 3 лет назад

ELSA-2022-7185: device-mapper-multipath security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2022-06669

около 3 лет назад

Уязвимость программного обеспечения управления драйверами для организации многопутевого доступа multipath-tools, связанная с ошибками при управлении привилегиями, позволяющая нарушителю повысить свои привилегии до root-пользователя

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3711-1

около 3 лет назад

Security update for multipath-tools

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3710-1

около 3 лет назад

Security update for multipath-tools

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3709-1

около 3 лет назад

Security update for multipath-tools

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3708-1

около 3 лет назад

Security update for multipath-tools

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3707-1

около 3 лет назад

Security update for multipath-tools

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-46cw-54vx-86g5

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-41974

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-41974

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-41974

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2022-41974

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword which is mishandled because arithmetic ADD is used instead of bitwise OR.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-41974

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to ...

CVSS3: 7.8
0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3715-1

Security update for multipath-tools

0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3714-1

Security update for multipath-tools

0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3713-1

Security update for multipath-tools

0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3712-1

Security update for multipath-tools

0%
Низкий
около 3 лет назад
rocky логотип
RLSA-2022:7192

Important: device-mapper-multipath security update

0%
Низкий
около 3 лет назад
oracle-oval логотип
ELSA-2022-7192

ELSA-2022-7192: device-mapper-multipath security update (IMPORTANT)

около 3 лет назад
oracle-oval логотип
ELSA-2022-7186

ELSA-2022-7186: device-mapper-multipath security update (IMPORTANT)

около 3 лет назад
oracle-oval логотип
ELSA-2022-7185

ELSA-2022-7185: device-mapper-multipath security update (IMPORTANT)

около 3 лет назад
fstec логотип
BDU:2022-06669

Уязвимость программного обеспечения управления драйверами для организации многопутевого доступа multipath-tools, связанная с ошибками при управлении привилегиями, позволяющая нарушителю повысить свои привилегии до root-пользователя

CVSS3: 7.8
0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3711-1

Security update for multipath-tools

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3710-1

Security update for multipath-tools

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3709-1

Security update for multipath-tools

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3708-1

Security update for multipath-tools

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3707-1

Security update for multipath-tools

около 3 лет назад

Уязвимостей на страницу